#VU117646 Use of uninitialized resource in FortiOS and FortiProxy - CVE-2023-37930
Published: October 24, 2025
FortiOS
FortiProxy
Fortinet, Inc
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to usage of uninitialized resources within the SSL-VPN webmode. A remote authenticated user can send specially crafted requests to the SSL-VPN websocket, trigger uninitialized usage of resources and perform a denial of service attack or execute arbitrary code on the device.